9.1. Internal Network Traffic Rules

These rules enable allowance of network traffic between individual Kerio Personal Firewall components during local or remote administration, connections to Kerio Technologies registration or check-for-new-version servers, etc.

Internal network traffic rules are hidden — they are not displayed in Personal Firewall GUI.

Remote configuration

This rule enables connection of the Personal Firewall GUI to the Personal Firewall Engine. If remote administration is allowed (see chapter 6.3. Preferences), connections from any host are allowed. If not, only connection from local host is enabled.

ConditionApplicationDirectionProtocolRem. portRem. address
Rem. adm. enabledkpf4ss.exeincomingTCP+UDP44334any
Rem. adm. disabledkpf4ss.exeincomingTCP+UDP44334localhost
Communication between the Personal Firewall GUI and the Engine

This rule enables the Personal Firewall GUI to connect to the Personal Firewall Engine (connection to local administration).

Note: This rule allows only local connections (i.e. connections to the Personal Firewall Engine installed on the same computer). In case of remote administration, the Personal Firewall GUI is considered as a standard network application and network traffic policy is applied (see chapter 7. Network Security).

ConditionApplicationDirectionProtocolRem. portRem. address
Unconditionalkpf4gui.exeoutgoingTCP+UDP44334any
Communication of the Personal Firewall Engine with the GUI

This rule allows the Personal Firewall Engine to connect to the Personal Firewall GUI (displaying of dialogs, notices, warning messages, etc.).

ConditionApplicationDirectionProtocolRem. portRem. address
Rem. adm. enabledkpf4ss.exeoutgoingTCP+UDPanyany
Rem. adm. disabledkpf4ss.exeoutgoingTCP+UDPanylocalhost
DNS queries

This rule allows Kerio Personal Firewall components to send DNS queries to any DNS server. DNS queries are used for mapping of host names which are later used for various purposes, such as displaying in Personal Firewall GUI, resolution of destination IP addresses when accessing a remote administration, etc.

ConditionApplicationDirectionProtocolRem. portRem. address
Unconditionalkpf4ss.exebothUDP53any
Unconditionalkpf4gui.exebothUDP53any
Sending crashdump files

If sending of crashdump files to Kerio Technologies (see chapter 6.3. Preferences) is enabled, this rule allows sending files to a corresponding server.

ConditionApplicationDirectionProtocolRem. portRem. address
Sending allowedassist.exeoutgoingTCPanycrashes.kerio.com
Logging of blocked pop-up and pop-under windows

If pop-up blocking is enabled (see chapter 14.1. The Ad Blocking tab), a special script is used for corresponding webpages that sends Personal Firewall Engine information about blocked pages. Traffic is performed by TCP protocol through a special port (44501).

ConditionApplicationDirectionProtocolRem. portRem. address
UnconditionalanyoutgoingTCP44501localhost
Update checker

This rule allows to access download servers where new versions of Kerio Personal Firewall are available.

Note: Server is not specified since various servers can be used for this purpose.

ConditionApplicationDirectionProtocolRem. portRem. address
Proxy serverkpf4ss.exeoutgoingTCPproxy_port*proxy_ip*
Direct accesskpf4ss.exeoutgoingTCPanyany

*) Resolution of IP address and port's proxy server is performed automatically by the Kerio Personal Firewall (the information is resolved from configuration of the operating system).

Product registration

This rule enables registration of Kerio Personal Firewall license (see chapter 3.2. Product registration) on a corresponding server.

ConditionApplicationDirectionProtocolRem. portRem. address
Proxy serverkpf4ss.exeoutgoingTCPprx_port*prx_ip*
Direct accesskpf4ss.exeoutgoingTCP443secure.kerio.com

*) Resolution of IP address and port's proxy server is performed automatically by the Kerio Personal Firewall (the information is resolved from configuration of the operating system).

Syslog

If logging to Syslog server (refer to chapter 16.3. Log Options) is enabled, this rule enables connection of the Personal Firewall Engine to the Syslog server.

ConditionApplicationDirectionProtocolRem. portRem. address
Syslog enabledkpf4ss.exeoutgoingUDPsslg_port*sslg_ip*

*) IP address and port of the Syslog server specified in the Syslog section of the Settings tab.